Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG
Cosa significa
CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.
Perché conta
L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.
Azioni consigliate
- Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
- Verificare sistemi esposti, accessi remoti e versioni rispetto all'advisory ufficiale.
- Confermare che backup offline e immutabili siano separati e ripristinabili.
- Correlare TTP e IOC pubblicati con la telemetria autorizzata del proprio perimetro.
Benefici operativi potenziali
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Cybersecurity Advisory Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG Last Revised May 11, 2023 Alert Code AA23-131A Related topics: Malware, Phishing, and Ransomware , Cyber Threats and Response , Securing Networks SUMMARY The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-27350 . This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF and enables an unauthenticated actor to execute malicious code remotely without credentials. PaperCut released a patch in March 2023. According to FBI observed information, malicious actors exploited CVE-2023-27350 beginning in mid-April 2023 and continuing through the present. In early May 2023, also according to FBI information, a group self-identifying as the Bl00dy Ransomware Gang attempted to exploit vulnerable PaperCut servers against the Education Facilities Subsector. This joint advisory provides detection methods for exploitation of CVE-2023-27350 as well and indicators of compromise (IOCs) associated with Bl00dy Ransomware Gang activity. FBI and CISA strongly encourage users and administrators to immediately apply patches, and workarounds if unable to patch. FBI and CISA especially encourage organizations who did not patch immediately to assume compromise and hunt for malicious activity using the detection signatures in this CSA. If potential compromise is detected, organizations should apply the incident response recommendations included in this CSA. Download the PDF version of this report (653kb): AA23-131A_Malicious_Actors_Exploit_CVE-2023-27350_in_PapercCut_MF_and_NG.pdf (PDF, 652.93 KB ) For a downloadable copy of IOCs (55kb), see: AA
Indicatori CISA verificabili
45 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T05:00:46.950764+00:00
Scarica STIX 2.1Questo allegato contiene 1 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.
| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| MD5 | e574ad52562fce9ea506f47e79516a52 | socks.exe |
| SHA-1 | d9f7a36db2a5117d73712fb93df23e3c2fc693fb | socks.exe |
| SHA-256 | 6bb160ebdc59395882ff322e67e000a22a5c54ac777b6b1f10f1fef381df9c15 | socks.exe |
| domain-name | study[.]abroad[.]ge | |
| ipv4-addr | 89[.]105[.]216[.]106 | |
| ipv4-addr | 80[.]94[.]95[.]103 | |
| ipv4-addr | 5[.]8[.]18[.]233 | |
| ipv4-addr | 46[.]4[.]20[.]30 | |
| ipv4-addr | 206[.]197[.]244[.]75 | |
| ipv4-addr | 198[.]50[.]191[.]95 | |
| ipv4-addr | 195[.]123[.]246[.]20 | |
| ipv4-addr | 194[.]87[.]82[.]7 | |
| ipv4-addr | 176[.]97[.]76[.]163 | |
| ipv4-addr | 172[.]106[.]112[.]46 | |
| ipv4-addr | 102[.]130[.]112[.]157 | |
| email-addr | prepalkeinuc0u[@]gmx[.]com | |
| email-addr | main-office[@]data-highstream[.]com | |
| email-addr | fimaribahundqf[@]gmx[.]com | |
| email-addr | decrypt[.]support[@]privyonline[.]com | |
| MD5 | f0c715e8318bb8a57b7072144753acac | update.dll |
| SHA-1 | 587bbb7ef50a72954d4ef9b22b27d4a377adc2fa | update.dll |
| SHA-256 | 0ce7c6369c024d497851a482e011ef1528ad270e83995d52213276edbe71403f | update.dll |
| ipv4-addr | 92[.]118[.]36[.]199 | |
| email-addr | tpyrcne[@]onionmail[.]org | |
| ipv4-addr | 192[.]184[.]35[.]216 | |
| url | http://192[.]184[.]35[.]216:443/4591187629[.]exe | |
| domain-name | upd488[.]windowservicecemter[.]com | |
| domain-name | winserverupdates[.]com | |
| domain-name | windowservicecenter[.]com | |
| domain-name | windowservicecentar[.]com | |
| domain-name | windowservicecemter[.]com | |
| domain-name | windowcsupdates[.]com | |
| domain-name | updateservicecenter[.]com | |
| domain-name | netviewremote[.]com | |
| domain-name | anydeskupdates[.]com | |
| domain-name | anydeskupdate[.]com | |
| MD5 | 46fe07c07fd0f45ba45240ef9aae2a44 | 46fe07c07fd0f45ba45240ef9aae2a44; undefined.exe |
| SHA-1 | b918f97c7c6ebc9594de3c8f2d9d75ecc292d02b | 46fe07c07fd0f45ba45240ef9aae2a44; undefined.exe |
| SHA-256 | c0f8aeeb2d11c6e751ee87c40ee609aceb1c1036706a5af0d3d78738b6cc4125 | 46fe07c07fd0f45ba45240ef9aae2a44; undefined.exe |
| domain-name | upd343[.]winserverupdates[.]com | |
| domain-name | ber6vjyb[.]com | |
| ipv4-addr | 216[.]122[.]175[.]114 | |
| ipv4-addr | 5[.]8[.]18[.]240 | |
| ipv4-addr | 5[.]188[.]206[.]14 | |
| ipv4-addr | 192[.]160[.]102[.]164 |
Provenienza
Allegato ufficiale CISA · 2023-05-13T04:30:45Z
SHA-512: ce50ed9c3ffc91458110bbbf621f993ed0b058559fbcb61fc18b3e707348a5b1096646dad1bc14300b0b7e5f06585aab621838bb0c60576054c9e9ebbf03a850
- Fonte
- CISA Cybersecurity Advisories
- Entità pubblicatrice
- CISA
- Tipo entità
- Autorità nazionale
- Area
- North America · US
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 11/05/2023 14:00
- Condivisione
- TLP:CLEAR
- MITRE ATT&CK
- T1033, T1059.001, T1059.003, T1068, T1486
- CVE
- CVE-2023-27350
- Classificazione
- Critica
- Paese indicato
- US
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.
Azione indicata dalla fonte
Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
Riferimenti tecnici ufficiali
- https://www.cisa.gov/sites/default/files/2023-05/aa23-131a_malicious_actors_exploit_cve-2023-27350_in_papercut_mf_and_ng_1.pdf
- https://www.cisa.gov/sites/default/files/2023-05/aa23-131a.stix_.xml
- https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf